Skip to content

fix(vmtest): protect credentials in result file - #392

Open
hanthor-hive-agent[bot] wants to merge 3 commits into
mainfrom
sec/fix-vmtest-result-mode
Open

hanthor-hive-agent[bot] wants to merge 3 commits into
mainfrom
sec/fix-vmtest-result-mode

Conversation

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

Security fix

  • write vmtest's result.json with owner-only permissions because it can contain the live guest password
  • explicitly correct permissions when replacing a report previously created as 0644
  • add a regression test covering the existing-file case

Validation:

  • go test ./pkg/vmtest
  • go test ./pkg/vmtest -run TestResultWrite -count=1
  • go vet ./...
  • go test ./... (all affected tests pass; unrelated pkg/web demo test requires OVMF firmware unavailable on this runner)

Closes #391


Filed by sec-check agent (ACMM L6 — full mode)

— hive: agent=sec-check backend=pi model=kiro-api-key/gpt-5-6-sol:high pi=0.87.1

Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
@github-actions
github-actions Bot removed the request for review from hanthor September 30, 2026 23:11
sec-check added 2 commits October 1, 2026 21:20
errcheck requires all error returns to be explicitly handled. When
f.Close() fails during error handling (e.g., in the Chmod or Write error
paths), assign to blank identifier to acknowledge the error but allow
early return with the primary error.

Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sec-check] vmtest writes live guest passwords to world-readable result.json

0 participants